answers
6 Steps of Incident Response Ans✓✓✓Preparation
Identification
Containment
Eradication
Recovery
Lessons Learned
Analysis Ans✓✓✓Create a copy of evidence for analysis and use
repeatable methods and tools during analysis
arp Ans✓✓✓Utility for viewing and modifying the local Address
Resolution Protocol (ARP) cache on a given host or server
see table of MAC address and IP addresses
Collection Ans✓✓✓Ensure authorization to collect evidence is
obtained, and then document and prove the integrity of evidence as it is
collected
curl Ans✓✓✓A command-line tool used to transfer data.
, hping Ans✓✓✓An open-source packet generator and analyzer for the
TCP/IP protocol that is used for security auditing and testing of firewalls
and networks
Allows us to craft the packet however we want
Identification (Forensics) Ans✓✓✓ensure the scene is safe, secure the
scene to prevent evidence contamination, and identify the scope of
evidence to be collected
Incident Response Ans✓✓✓A set of procedures that an investigator
follows when examining a computer security incident.
ipconfig/ifconfig Ans✓✓✓Utility that displays all the network
configurations of the currently connected network devices and can
modify the DHCP and DNS settings
IPfix Ans✓✓✓Used on the back end of service management
journalctl Ans✓✓✓A Linux command line utility used for querying and
displaying logs from journald, the systemd logging service on Linux
Log Files Ans✓✓✓A file that records either events that occur in an
operating system or other software runs, or messages between different
users of a communication software